CVE-2020-7595: Loop with Unreachable Exit Condition ('Infinite Loop')
(updated )
xmlStringLenDecodeEntities in parser.c in libxml2 has an infinite loop in a certain end-of-file situation.
References
- lists.opensuse.org/opensuse-security-announce/2020-05/msg00047.html
- cert-portal.siemens.com/productcert/pdf/ssa-292794.pdf
- gitlab.gnome.org/GNOME/libxml2/commit/0e1a49c89076
- lists.debian.org/debian-lts-announce/2020/09/msg00009.html
- lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/545SPOI3ZPPNPX4TFRIVE4JVRTJRKULL/
- lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/5R55ZR52RMBX24TQTWHCIWKJVRV6YAWI/
- lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/JDPF3AAVKUAKDYFMFKSIQSVVS3EEFPQH/
- nvd.nist.gov/vuln/detail/CVE-2020-7595
- security.gentoo.org/glsa/202010-04
- security.netapp.com/advisory/ntap-20200702-0005/
- us-cert.cisa.gov/ics/advisories/icsa-21-103-08
- usn.ubuntu.com/4274-1/
- www.oracle.com/security-alerts/cpujul2020.html
- www.oracle.com/security-alerts/cpuoct2021.html
Detect and mitigate CVE-2020-7595 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →